Data Processing Agreement (DPA)
Last Updated: 21st November 2025
This Data Processing Agreement forms part of the agreement for the provision of Envolve’s services.
Between:
Envolve Technology Limited (Company No. 08548197) (“Processor”)
and
[Client Name] (“Controller”)
This Data Processing Agreement (“Agreement”) sets out the terms on which the Processor processes Personal Data on behalf of the Controller in connection with the provision of Envolve’s chatbot services.
1.Purpose
This Agreement governs the processing of personal data by the Processor on behalf of the Controller for delivery of Envolve’s chatbot services.
2.Roles
The Controller determines the purpose and means of processing. The Processor processes data solely on the basis of documented instructions from the Controller.
3.Nature of Processing
Processing includes collection, transmission, storage, and analysis of chatbot interaction data for service delivery, performance measurement, and system improvement.
4.Categories of Data
Data may include conversation text, timestamps, and optional personal data voluntarily provided by users. Sensitive data is not required and should not be submitted.
5.Sub-Processors
The Processor may use approved sub-processors (for example, infrastructure or hosting providers). The Controller will be notified of material changes to the list of sub-processors where required.
6.Security
The Processor implements appropriate technical and organisational measures to ensure the confidentiality, integrity, and availability of personal data, taking into account the nature of the processing and the risks to data subjects.
7.Data Subject Rights
The Processor shall, where feasible and taking into account the nature of the processing, assist the Controller in responding to requests from data subjects to exercise their rights under applicable data protection laws.
8.Data Breaches
The Processor shall notify the Controller without undue delay upon becoming aware of any personal data breach affecting personal data processed on behalf of the Controller and shall provide reasonable assistance in relation to any investigations or notifications required.
9.Deletion or Return of Data
Upon termination or expiry of the services, the Processor will delete or return personal data processed on behalf of the Controller, unless applicable law requires the retention of such data.
10.International Transfers
Any transfers of personal data outside the UK carried out by the Processor shall comply with UK GDPR requirements and shall be subject to appropriate safeguards, such as standard contractual clauses or other approved transfer mechanisms.
11.Governing Law
This Agreement and any dispute or claim arising out of or in connection with it shall be governed by and construed in accordance with the laws of England & Wales.
